HomeHacker FilesSalt Typhoon cyberattack: Did Chinese hackers steal data on every American?
September 5, 2025

Salt Typhoon cyberattack: Did Chinese hackers steal data on every American?

NetworkTigers examines how the Chinese state-backed Salt Typhoon cyberattack infiltrated telecoms, military, and critical infrastructure across more than 80 countries.

A Chinese state-backed threat group known as Salt Typhoon has shaken the global security community. The campaign infiltrated telecommunications, military, transportation, and critical infrastructure networks in over 80 countries and is being described as one of the widest cyber-espionage operations ever uncovered.

According to a joint advisory from U.S. and allied cybersecurity agencies, Salt Typhoon compromised carriers and infrastructure across dozens of industries worldwide. Investigators said the operation demonstrated an “unrestrained” and “indiscriminate” style, signaling a shift from narrow intelligence-gathering to broad surveillance of governments, companies, and civilians.

Politics, privacy, and the American target list

The breach extended beyond institutions to individuals. Data from millions of Americans was reportedly exposed, including call records, text logs, and geolocation information. Targets included high-profile political figures and campaign staff, indicating the group’s willingness to sweep up both high-value and incidental intelligence.

Salt Typhoon exploited known weaknesses in aging telecom infrastructure, particularly lawful intercept frameworks intended for law enforcement surveillance. That abuse raises concerns that attackers may have gained visibility into U.S. wiretapping infrastructure itself.

Telecom carriers as a global listening post

At least six major U.S. telecom providers — including AT&T, Verizon, T-Mobile and Lumen — were infiltrated. That access allowed the attackers to monitor voice traffic and metadata at scale, effectively mapping American communications flows from inside the carriers’ networks.

Even U.S. military networks were not immune. A U.S. Army National Guard system remained compromised from March through December 2024, showing that Salt Typhoon was willing to enter defense domains, not just the private sector.

Hacking tools with nation-state fingerprints

Salt Typhoon deployed precision tooling: operating system–level rootkits such as Demodex, anti-forensic utilities designed to wipe traces, and exploits against networking gear like routers, VPN appliances, and firewalls.

According to the U.S. government, the campaign was backed by Chinese contractors fronting for the Ministry of State Security. Three firms — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong, and Sichuan Zhixin Ruijie — have been identified, two of which already sit under U.S. sanctions.

A rare chorus of international condemnation

The scope of Salt Typhoon drew a rare multinational response. Agencies from the U.S., U.K., Japan, Germany, Canada, and at least seven other nations issued coordinated advisories urging operators to update legacy infrastructure and hunt for persistence mechanisms.

British officials disclosed that critical national infrastructure was breached in the U.K., escalating concern that China’s campaign could affect military readiness, energy systems, and transport safety.

Lessons for those guarding the backbone

Legacy systems are liabilities. Telecom lawful intercept platforms and signaling systems like SS7 remain structurally weak. Without segmentation and 24/7 monitoring, they become long-term footholds for adversaries.

Carriers are the crown jewels. Compromise at the telco level enables attackers to map entire geographies of communications, far beyond a single business or agency.

Blurred lines matter. By moving through Chinese contractors, Beijing gains plausible deniability while scaling capability.

Allied response is hardening. For perhaps the first time at this global level, more than a dozen nations called out China’s role simultaneously.

Why Salt Typhoon marks a turning point

Salt Typhoon is more than another headline breach. It highlights how state adversaries are embedding within the world’s communications fabric — where aging surveillance systems meant for police and intelligence are now being hijacked for foreign espionage.

For operators, the lesson is simple: patch, segment, and monitor relentlessly. Every overlooked legacy port or intercept node is a beachhead waiting to be claimed.

Sources

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Katrina Boydon
Katrina Boydon
Katrina Boydon is a veteran technology writer and editor known for turning complex ideas into clear, readable insights. She embraces AI as a helpful tool but keeps the editing, and the skepticism, firmly human.

Popular Articles